Cannot Replicate after upgrading domain functional level

Hello, 
Parent and child domain. Parent domain (forest) still in domain functional level 2003. However, child domain i just updated to domain functional level 2008 R2. Now replication is not working. I believe the issue is dns, but i do not know what could be different
the names have not changed? This is a two way transitive trust between domains.
Frequent messages from dcdiag dns, are 
no DNS RPC connectivity (although i have tried restarting dcom, netbios and frs)
Also in event viewer many 13508 errors
Any help is greatly appreciated thank you.

Have you restarted the DCs after that you raised the functional level? The password of the krbtgt account is reset when the DFL is raised from 2003 -> and sometimes the DCs need to be restarted for the authentication to succeed up to the root.
If you from a Windows Server 2008 R2 DC run dcdiag /test:dns /E dose it report any errors?
Enfo Zipper
Christoffer Andersson – Principal Advisor
http://blogs.chrisse.se - Directory Services Blog

Similar Messages

  • Logon failure after upgrade Windows 2003 domain functional level and schema

    Before upgrade:
    Windows 2003 Std server: Domain functional level 2000, Schema verion 30
    Crystal Report XI R2: Authentication: Windows AD
    Logon OK.
    After Upgrade:
    Windows 2003 Std + Windows 2008: Domain functional level 2003, Schema verion 44
    Crystal Report XI R2: Authentication: Windows AD
    Logon Error: An error has occurred: java.lan.NullPointerException
    Is it a Tomcat problem?  OR Java runtime problem?  OR XI R2 problem?
    Anyone can help to fix it!?  Thanks!!

    OK, I try again in the testing lab and simplify the combination.  We only consider Windows 2003 ONLY.
    Before AD upgrade:
    AD/Domain Controller: Windows 2003 Std server: Domain functional level 2000, Schema verion 30
    Crystal Report XI R2: run on Windows 2003 memeber server
    Operating OS: Windows XP/Vista/7: Authentication: Windows AD
    Logon OK.
    Upgrade cmbination 1
    Step 1:
    Upgrade Domain controller: Windows 2003 to Windows 2003 R2 (Domain functional level 2000, Schema verion 31 )
    Crystal Report XI R2: run on Windows 2003 memeber server
    Operating OS: Windows XP/Vista/7: Authentication: Windows AD
    Logon OK.
    Step 2:
    Upgrade Domain Functional Level: Windows 2003 R2 (Domain functional level 2003, Schema verion 31)
    Crystal Report XI R2: run on Windows 2003 memeber server
    Operating OS: Windows XP/Vista/7: Authentication: Windows AD
    Logon Fail
    Logon Error: An error has occurred: java.lan.NullPointerException
    Upgrade combination 2
    Direct upgrade Domain Functional Level: Windows 2003 (Domain functional level 2003, Schema verion 30)
    Crystal Report XI R2: run on Windows 2003 memeber server
    Operating OS: Windows XP/Vista/7: Authentication: Windows AD
    Logon Fail
    Logon Error: An error has occurred: java.lan.NullPointerException
    In this testing, we can conclude that the Domain Functional Level upgrade from 2000 to 2003. The MI logon will fail.
    Q1. Crystal Report XI R2 cannot run on Windows 2003 server (Domain Functional Level: 2003)?
    Q2. If Crystal Report XI R2 can run on Domain Functional Leve: 2003, how to fix our problem?
    Do you have any idea to help us?  Thanks!
    Edited by: Initiator on Jul 20, 2010 6:22 AM

  • Lingering 2003 DC causing Domain Functional Level Upgrade fail

    Got that one too :(
    I can't find hide nor hair of this darn beast anywhere

    Have a DEAD 2003 DC - check
    Have removed it from AD via GUI (ADUC) deletion - Check
    Cleaned up DNS - Check and double check
    Review LostandFound container in ADSI edit - Check - No objects present
    Right click Domain Name in ADUC, select Raise Domain Functional level - F A I L
    Run through NTDSUTIL Metadata cleanup steps (MS technet article) - The server object isn't there
    What am I missing here? I've gone back over DNS, searched for the computer object, rechecked ADSI LostandFound, rechecked NTDSUTIL .. I'm at a hard loss to figure out what's stopped the Functional Level upgrade.
    Any ideas?
    This topic first appeared in the Spiceworks Community

  • Domain functional level upgraded to 2008 r2 native mode but query states 2003

    Nothing :(

    I raised the domain functional level last night to 2008 r2 native mode and after allowing everything to sync i ran the command get-addomain .domainmode and it came back ast windows2003forest. 
    I dont understand why it is showing up this way, we removed all of the 2003 domain controllers and server from our network before doing this...Any suggestions?
    This topic first appeared in the Spiceworks Community

  • Missing nodes in new GPO objects after adding ADMX to DC (Server 2008 Domain Functional Level 2003)

    Hello,
    we discovered an issue in GPO console.
    DCs: multiple 2008 there is one 2003DC somewhere over the rainbow (don't ask why) :)
    Domain Functional Level is 2003.
    In June I added Policydefinitions folder into Policy folder in sysvol\domain_name.
    I did this for adding ADMX.
    Today we found missing nodes when adding new GPO objects and trying to modify them.
    Under Computers\Administrative Templates there is only ADMX node. No Administrative Templates with sub nodes: Systeme, Network, Printes, Windows Components.
    When edit old GPOs There is Administrative Templates in Administrative Templates with ADMX folder. SEE Screenshot.
    My colleague insists that it happened after I made changes by adding ADMX things. Looks that he is right.
    Please any help on this issue... How to get back nodes for managing new GPOs as it was before adding ADMX.
    Is this something known? I didn't find any prerequisites before adding PolicyDefinistions folder.
    Thanks.
    "When you hit a wrong note it's the next note that makes it good or bad". Miles Davis

    Meinolf,
    1. I would like to know if it is normal behaviour that after creating a Central Store (adding PolicyDefinitions folder into Policies) Classical Administrative Templates will not appear for any new GPO (they do exist to all previously created) see
    picture
    2. I followed the links. And eventually will use the script for cleaning up duplicate adms  in all GPOs. It is great feature of ADMX. But first I would like to bring back the option of Admin Templates.
    So I downloaded latest 2012 ADMXs. Run setup on my computer. Now I have Policydefinitions folder containing new ADMXs with languages (culture) folders.
    Am I right? I have to copy all *.admx files to my Central Store Policydefinitions folder and all En admls drop to En-Us language folders. What will happen if I will add Fr-Fr? Would it be correct to have 2 languages for the same admxs. And how they will
    appear. Or it will depend on OS language were GP console will be opened?
    No conflict to expect?
    I will do this "surgery" after your answer.
    Thanks for pointing out..
    "When you hit a wrong note it's the next note that makes it good or bad". Miles Davis

  • Raise domain functional level

    Hi All,
      What all that need to be considered before raising domain / forest functional level.

    Hi channavera,
    Some items that you want to consider are what OS are you running for all your DC's in the domain/forest. This is important, since you have to have a certain level for the functional level. For example, if you want to raise up to functional level of 2012,
     you will need to make sure any DC's running 2008 or lower are upgraded before you do so. Raising the functional level will change up the schema for the domain, making it incompatible with the lower OS's.  If you are going to continue to run 2008
    server in the domain/forest, you will want to only raise the functional level to 2008.  Also, keep in mind, you cannot go to a lower functional level (i.e. if you go to 2012, you cannot go back to 2008) except under very specific circumstances.  
    I know what I brought up is not the only consideration, but a big one, as it basically determines what functional level you want to use for the domain/forest.
    Also, this technet site goes over what changes for each level. Understanding AD Functional levels

  • Raising Domain Functional level

    We have 75 domain Controllers in our Org and current Domain Functional level is 2003. We have a mix setup where all versions of OS are available starting from 2003. A large no of applications are also integrated with our current Active Directory.
    My concern is, If I raise my Domain Functional level to 2008 then what are the consequences we might face in terms of accessing legacy applications.
    Please let me know the checklist which we need to follow and incase of any failure then what will be the rollback procedure.
    Looking forward for your valuable inputs. 

    Hi, 
    I agree with others. Once the Functional Level has been upgraded, new
    servers running on lower versions cannot be added
    as Domain Controllers to the domain or forest. If all the DCs in the domain is server 2008 and later version, we can raise the function level of the domain to get more advanced features.
    > If I raise my Domain Functional level to 2008 then what are the consequences we might face in terms of accessing legacy applications.
    For this question, make sure that the applications in the domain are compatible with the new functional level
    For detailed information about how to raise function level, we can refer to the following link:
    Raising the Functional Levels
    http://technet.microsoft.com/en-us/library/cc771949(v=WS.10).aspx
    Best Regards,
    Erin

  • Exchange Server 2003 SP2 - Forest and Domain Functional Level Limitations

    Hi All
    Bit of a legacy question and theres not much clarity out there..
    I need to confirm the highest DFL and FFL Supported by Microsoft for Exchange 2003 SP2?
    We currently have a mix of 2003 R2 and 2008 R2 domain controllers with the FFL and DFL currently set at 2003 R2.
    The plan is to move to Exchange 2010 in the very near future, so the question is do we need to wait until we upgrade to Exchange 2010 Before upgrading the DFL and FFL to 2008 R2?
    From what Ive read we will need to complete the Exchange upgrade first before moving forward with the functional level upgrades..
    Thanks in advance
    Bull

    Hi Bull,
    As Ed mentioned, Exchange server 2003 and Exchange 2010 support Windows Server 2003 domain functional level and Windows Server 2003 forest functional level, also supported in higher environment.
    More details about it, please refer to “Supported Active Directory environment” section:
    http://technet.microsoft.com/en-us/library/ff728623(v=exchg.150).aspx
    Note that we cannot add new DCs which are the less version of Windows Server
    cannot be added to the domain or forest. More details about
    the Impact of Upgrading the Domain or Forest Functional Level, for your reference:
    http://blogs.technet.com/b/askds/archive/2011/06/14/what-is-the-impact-of-upgrading-the-domain-or-forest-functional-level.aspx
    Best Regards,
    Allen Wang

  • Lync 2013 and Raising Forest/Domain Functional Level?

    My current forest and domain functional levels are 2008 R2. I know I can safely upgrade the functional levels in most cases, but I want to specifically know with regards to Lync.
    Our entire environment, including Lync, is running on Windows Server 2012 R2. (We have no domain joined clients.) We are running Lync 2013 Standard with all the latest updates.
    Can I safely raise the forest and domain functional levels to 2012 R2 without impacting Lync?

    Hi,
    Yes, you can raise Forest and domain function level to Windows Server 2012 R2 without issue.
    After raising Forest\domain function level, the new features that rely on the functional level are generally limited to AD itself. Regardless, changing the Domain or Forest Functional Level should have no impact on an application that depends on
    Active Directory.
    More details:
    http://blogs.technet.com/b/askds/archive/2011/06/14/what-is-the-impact-of-upgrading-the-domain-or-forest-functional-level.aspx
    Best Regards,
    Eason Huang
    Eason Huang
    TechNet Community Support

  • Domain Functional Level: 2008 R2 to 2012 R2

    My current forest and domain functional levels are 2008 R2. I know I can safely upgrade the functional levels in most cases, but I want to specifically know with regards to Lync.
    Our entire environment, including Lync, is running on Windows Server 2012 R2. (We have no domain joined clients.)
    Can I safely raise the forest and domain functional levels to 2012 R2 without impacting Lync?

    you can easily upgrade the funtional level without any issues since you have all the Domain Controllers on Win server 2008R2.
    http://support2.microsoft.com/kb/2869728/en-us
    For more details : Listed below link has the table which shows the effects of upgrading the domain functional levels to Windows 2012
    http://technet.microsoft.com/en-us/library/understanding-active-directory-functional-levels
    pankaj(MCT)

  • AD FS Across Differing Domain Functional Levels

    My customer needs to implement AD FS for single sign on due to a cloud based email solution they recently implemented. The problem is, their domain controllers are Server 2003 (non-R2) at a functional level of 2003 mixed mode. They should be able to raise
    to 2003 native if necessary however. Their solution is to create a new 2008 domain and implement a two-way trust, running AD FS in the new domain serving the clients in the 2003 domain.  This way should be quicker than upgrading their current domain
    which would be a rather large project due to their size and complexity. 
    Are there any gotcha's I should know about with doing it this way?  I have verified that we can create the two-way trust between domains of these functional levels, and AD FS can service clients in a trusted domain, but I am not entirely sure if AD
    FS will care that the trusted domain is 2003 non-R2.  Can anyone confirm if this will be a feasible scenario? 
    Thanks very much!!
    Wraith

    Hi
    Wraith,
    In addition, if you are not using Windows Server 2012 or above as ADFS server, you will be fine with Windows 2003 mixed mode.
    “Since ADFS does not require Active Directory functional-level modifications to operate successfully. However, if you are using Windows NT token–based applications and
    you want a token to be generated using Kerberos Service-for-User (S4U), the domain functional level must be Windows 2000 native or Windows Server 2003”, quoted form below article:
    Appendix A: Reviewing ADFS Requirements
    http://technet.microsoft.com/en-us/library/cc778681(v=WS.10).aspx
    More information for you:
    ADFS and Domain Functional Level
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/5cc0e898-eae2-46ce-8491-5ccf61380423/adfs-and-domain-functional-level?forum=winserverDS
    ADFS requirements
    http://technet.microsoft.com/en-us/library/cc727972(v=WS.10).aspx
    Best Regards,
    Amy

  • SCSM 2012 with 2003 domain functional level supported?

    All,
    I am running SCCM 2007. Now I need to install Service Manager 2012SP1. Domain functional level is 2003 with 2008 DC.
    will this allow me to install SCSM 2012SP1 with full features? or will it be reduced functionality?
    will there be any schema extension when I install SCSM 2012? pleas note we already have SCCM 2007 running.
    can I upgrade SCCM 2007 to SCCM 2012?  
    it would be helpful if you could share some link about whether its possible or not.
    Thanks.
    KailashC

    Thomas,
    Thanks for your response. Can I do a direct upgrade SCCM 2007 SP3 to SCCM 2012 or do I need to plan a migration? I mean fresh install SCCM 2012 and then migrate the data over ?
    Thanks.
    KailashC

  • Unable to Raise domain functional level

    I am installing a Server 2012 std.  in a single domain. The current DC is Server 2008 std. When I try to raise the domain functional level to at least 2003 it gives me an error.
    I did the save as and viewed the error message.  Apparently some time in the past they had a Server 2000 and active directory still has the entries that is preventing the domain from being raised.  I removed the old server from AD CU and restarted
    the server.  Still will not let me raise the level, same error.  Do I need to use ADSI edit and remove all the entries also?  What about DNS entries?
    Thank you for a rapid answer.
    Wade Harris

    Hi Wade,
    Please refer to following KB and check if can help you. (Please back up before all operations. That will help us to avoid unexpected issues.)
    How to remove data in Active Directory after an unsuccessful domain controller demotion
    In addition, please also use dcdiag
    command-line tool to verify domain controller health.
    If any update, please feel free to let me know.
    Hope this helps.
    Best regards,
    Justin Gu
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • What is the effect if I Raise my domain functional level to Windows Server 2012 R2 ?

    Hi,
    my current servers:
    Domain Controllers= Windows Server 2012 R2 (current domain functional level is windows 2008 R2)
    Mail servers= Exchange 2010 SP3 on Windows 2008 R2
    Lync= Lync 2010 on Windows server 2008 R2
    What is the effect if I Raise my domain functional level to Windows Server 2012 R2 ?
    I am very worried about Exchange & Lync if we do this action
    please advice

    Do not raise the forest functional level higher if you have or will have any domain controllers running
    an earlier version of Windows Server , which is (windows Nt4.0,  Window 2000 or windows 2003)
    but as a matter of fact I dont see any of those in your network so you can easily upgrade the funtional level without any issues
    Listed below link has the table which shows the effects of upgrading the domain functional levels to Windows 2012
    http://technet.microsoft.com/en-us/library/understanding-active-directory-functional-levels
    http://www.arabitpro.com

  • Active Directoy Domain Functional Levels - Recommendations / Requirements / Minimum ?

    Hi All,
    What are the Active Directoy Domain Functional Levels requirements for BizTalk 2013 R2?
    Would be useful to know the same for BizTalk 2010 also.
    I have been looking for sometime but cannot find any documentation.
    We are planning on installing BizTalk 2013 R2 and we have a domnain functional level of 2008.
    Many Thanks..

    Would be useful to know the same for BizTalk 2010 also.--> I am sure you would have checked this
    blog post by Sandro, if not, Have a look.
    Installing BizTalk Server 2010
    in a Basic Multi-Computer Environment: The need for a Domain Controller – Windows Groups and Service Accounts (Part 2)
    Hope this helps for you.
    Greetings,HTH
    Naushad Alam
    When you see answers and helpful posts, please click Vote As Helpful, Propose As Answer, and/or
    Mark As Answer
    alamnaushad.wordpress.com

Maybe you are looking for

  • Standard Report not Displaying 'SAVE LAYOUT' Option

    Dear All, Using Tcode VF44, i am getting output list.But in that list when i click on select layout option from toolbar its not displaying 'save layout' Option. can anybody give me soln for the same.How can i get that option? Regards, Mayank

  • How do I reformat my backup disk?

    I deleted a file from an external hard drive that I use to make Time Machine backups from my MacBook Air. Apparently I did something wrong (I moved the file to trash on my computer, but didn't empty trash before ejecting the disk, I suspect that the

  • Accessing individual server in load-balanced cluster not working as expected

    We have a cluster set up with multiple managed servers and hardware load           balancers sitting in front to direct traffic. We have the frontend host           configured to be the dns name of the single URL for the cluster, which maps          

  • Failover - file system ownership has been usurped!

    I have 2 PPC metadata controllers, 15 mixed workstation Intel/PPC and 3 Xserve RAID. I have worked without problems for more than a year. But since a month ago, i have 3 auto failover processes about midnight and 1 time about 9am. [0211 00:09:03] 0xb

  • Tablesusing in the work practice of Oracle Database 10g-SQL Fundam 1

    I want scripts sql builder for the tables (LOCATIONS, DEPARTMENTS, JOB_HISTORY, COUNTRIES, EMPLOYEES, JOBS, REGIONS, JOB_GRADES) use in the work practice of Oracle Database 10g-SQL Fundamentals(I) I thank you Youssef BENABDELLAH